This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

LIMIT ON DOWNLOAD BANDWITH WITH SG 115

Hi, 

We have 2 sophos UTM SG115 (box A and box B) which are connected by a VPN link on 2 different locations.

Both SOPHOS are of the same revision, 3 and has the latest firmware updates (9.706-9).

A box is behind a 200 Mb symetric optical fiber acces with SFP port directly connect to the optical fiber.

B box is behind a 800Mb(d)/400Mb(u) optical fiber access, behind the ISP box. 

Testing B speed on the internet, it can reach 250Mb(d)/343Mb(u).

Testing A several times at different schedules, while acheiving 190 Mb(d), it can't exceed 100 Mb(u), like it has some stop, some blocking.

Testing A has be done directly on the SOPHOS LAN port diconnected from the office lan.

 An ISP technician came at the office, tested the link in same conditions, with a PC directly connected to the LAN port of a basic entry level firewall router, it reached indeed the throughput of the internt acess (190 Mb(d)/189 Mb(u)), so the internet access hasn't any blocking.

 Our SOPHOS integrator, talked about some blocking on some SG 115 revisions, but as they are of the same revision, this explanation doesn't match.

 Any idea or suggestion?

Thank's for help.

Olivier



This thread was automatically locked due to age.
  • The 115 is probably a bit on the low end for connections of those speeds. But there are some easy things to check.

    Do you have QOS enabled? if so disable and test.

    Do you have IPS enabled? if so disable and test.

    Other than that maybe a speed/duplex negotiation issue on the wan interface?

  • Thank's, QOS is disabled, and we've tried both IPS enabled and disblade, it doesn't change the limit.

    Other than that maybe a speed/duplex negotiation issue on the wan interface? In this case, why behind an ISP box, we can reach 384 Mb(u)?

    Is it the SFP Port negociation?

  • What exact model transceiver is it? Have you tried a different one?

  • Salut Olivier and welcome to the UTM Community!

    I agree with SandyMan that the 115 isn't powerful enough for a 800Mb(d)/400Mb(u) connection when testing with a single device.  Test with 5 units simultaneously measuring speed.

    Also, some fibre units behave badly with auto-negotiated speed/duplex.  See if #7.7 in Rulz (last updated 2021-02-16) has any effect on your throughput in both locations.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Hi, thank you both for you help.

    Problem is just why one box can sustain 300 Mb upload why the other is stuck to 100 Mb, so as the ISP link is given for 200 Mb symetric.

    I've opened a ticket to SOPHOS via our integrator, but it takes time. Furthermore iperf test give very different results than npef (web based).

    So for the moment it's not very clear where the bottlenck is. I'll let you know.

    Thank you again.

    Olivier